Privacy Policy

Last updated: 1 October 2026

Short version: OpenPocket POS is offline-first. Your shop data — products, sales, customers and staff — is stored on your own device and is not sent to us. We don't show ads, we don't use trackers, and we never sell your data. A few features are optional and only run if you turn them on (see below).

1. Who this applies to

This policy covers the OpenPocket POS mobile app and the website at openpocket.wraplet.app ("OpenPocket", "the app", "we", "us"). By using the app you agree to this policy.

2. Data stored on your device

Everything you enter to run your shop is saved locally on your phone in a private database and never leaves the device unless you choose to enable cloud backup (section 4b):

No account is required to use the app, and we have no access to this on‑device data.

3. Permissions we ask for

PermissionWhy
CameraTo scan product barcodes and take product photos. Images are saved on your device.
Photos / mediaTo let you pick an existing photo as a product image.

We do not request location, contacts, microphone or background access.

4. Optional features that use the internet

The app works fully offline. The following only send data externally when you use them:

4a. Barcode lookups

When you scan or enter a barcode to add a product, the app may send that barcode to Open Food Facts, a free public product database, to fetch a product name and image. Only the barcode is sent — none of your shop, sales or customer data.

4b. Cloud backup & sync (optional, paid)

If you turn on Cloud backup, a copy of your shop data is stored on our backend (hosted on Cloudflare) so you can back it up and sync it across your devices. Access is protected by a private shop code that you control. We store this data only to provide the sync service, do not use it for any other purpose, and never sell or share it. You can stop syncing at any time, and you can ask us to delete your cloud copy (section 7).

4c. Subscriptions

The Cloud backup plan ($2/month) is sold and billed through Google Play, and subscription status is managed via RevenueCat. Your payment card details are handled by Google and never reach us. We receive only an anonymous subscription identifier and its active/expired status.

5. Third parties (sub‑processors)

We keep these to a minimum, and each only receives what the feature above needs:

ServiceUsed forData it sees
Open Food FactsProduct barcode lookupsThe barcode you scanned
CloudflareHosting cloud sync & the websiteYour shop data (only if sync is on)
Google PlaySubscription billingYour Google payment account
RevenueCatSubscription statusAnonymous subscription ID & status

6. What we don't do

7. Keeping, deleting and exporting your data

On your device: data stays until you delete it. You can export it any time (CSV and a full backup file) from the app, and you can wipe everything by clearing the app's storage or uninstalling it.

In the cloud (if you enabled sync): turning sync off stops new data being uploaded. To have your cloud copy deleted, contact us (section 11) with your shop code and we will remove it.

8. Security

On‑device data is stored in the app's private storage. Cloud sync travels over encrypted HTTPS and is scoped to your shop code. Staff PINs are stored only as salted hashes. No method of storage or transmission is 100% secure, but we take reasonable measures to protect your information.

9. Children

OpenPocket POS is a business tool and is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect data from children.

10. Your rights

Because your data lives on your device, you already control it directly — view, edit, export or delete it in the app at any time. Where laws such as the GDPR or CCPA apply, you may also have the right to access, correct or delete data we hold through cloud sync, and to object to or restrict its processing. Contact us to exercise these rights. Cloud data may be processed on servers outside your country; we rely on our providers' safeguards for such transfers.

11. Contact

Questions or data requests: support@wraplet.app. You can also open an issue on our GitHub repository.

12. Changes

We may update this policy as the app evolves. We'll change the "Last updated" date above and, for significant changes, note them in the app or on this page.